US8381306B2

Translating role-based access control policy to resource authorization policy

Summary by NHIP

RBAC to ACL Policy Translation

The method translates role-based access control policies into resource authorization models using a computer store. It defines enterprise roles within scopes and maps them to access control lists for networked resources.

Claim Score by NHIP

Read claim 10, the broadest

Abstract

Translation of role-based authoring models for managing RBAC roles to resource authorization policy (RAP), such as ACL-based applications, is provided. A generic RBAC system is defined from which mappings to other authorization enforcement mechanism make possible the translation of RBAC roles to resource authorization policies applied to resources managed by a resource manager, e.g., a file system resource manager. An implementation is described that uses Windows Authorization Manager as a storage mechanism and object model to manage object types and relationships translated from an RBAC system.

US8381306B2, drawing sheet 1
Sheet 1 of 9

Term

2.2 yearsleft in the term

Expires 22 November 2028, including 907 days of term adjustment.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

20 claims: 3 independent, 17 dependent

  1. 1
    A method comprising:providing in a computer, a role based access control (RBAC) store, the RBAC store defining at least one scope wherein each scope represents a set of resources in a networked computing environment;providing in the RBAC store, at least one role definition and at least one role assignment;defining in the RBAC store, based at least in part on the at least one role definition and the at least one role assignment, at least one enterprise role, each enterprise role including a set of permissions that are assigned to principals in a given scope;and using the RBAC store for translating the at least one scope, the at least one enterprise role and at least one resource group representing a role based access control (RBAC) policy to a resource authorization policy model, the RBAC policy mappable to at least one access control list (ACL) in the networked computing environment for configuring an underlying resource authorization policy.
  2. 10
    Broadest claimClaim Score 41, average(NHIP)A computer readable storage medium that is not a transient signal, the computer readable storage medium configured to store instructions that, when executed, provide for:defining in a role based access control (RBAC) store, scope data representing at least one scope wherein each scope represents a set of resources in a networked computing environment;providing in the RBAC store, role definition data defining at least one role, each role including a set of permissions that are assigned to principals in a given scope;and using the RBAC store for translating the at least one scope and the at least one enterprise role representing a role based access control (RBAC) policy to a resource authorization policy model, the RBAC policy mappable to at least one access control list (ACL) in the networked computing environment for configuring an underlying resource authorization policy.
  3. 15
    A computer readable storage medium that is not a transient signal, the computer readable storage medium configured for storing computer executable instructions that, when executed, provide an authoring tool for creating role based access control policy to be enforced in a networked computing environment including authorizations based on resource authorization policy, the authoring tool comprising:means for defining in a role based access control (RBAC) store, at least one scope wherein each scope represents a set of resources in the networked computing environment;means for providing in the RBAC store, at least one role definition, each including a set of permissions that are assigned to principals in a given scope;and means for using the RBAC store for translating the at least one scope, the at least one application role and the at least one resource group representing the role based access control (RBAC) policy model for configuring at least one underlying access control list (ACL) in the networked computing environment.